Home

Description

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

PUBLISHED Reserved 2024-05-09 | Published 2024-11-13 | Updated 2024-11-19 | Assigner hackerone




HIGH: 7.2CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Product status

Default status
unaffected

2024 November Security Update (custom) before 2024 November Security Update
affected

2022 SU6 November Security Update (custom) before 2022 SU6 November Security Update
affected

References

forums.ivanti.com/...November-2024-for-EPM-2024-and-EPM-2022

cve.org (CVE-2024-34784)

nvd.nist.gov (CVE-2024-34784)

Download JSON